The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get the List of Active Botnets

Prev Next

This URL gets the list of active botnets in the domain.

Resource URL

GET /domain/<domain_id>/activebotnets?includeChildDomain=<includeChildDomain>&&duration=<duration>

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
domain_id Domain id Number Yes
includeChildDomain Should the child domains be included Boolean No
duration Duration can be:
  • LAST_5_MINUTES
  • LAST_1_HOUR
  • LAST_6_HOUR
  • LAST_12_HOUR
  • LAST_24_HOUR
  • LAST_48_HOUR
  • LAST_7_DAYS
  • LAST_14_DAYS
String No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
botnetDetailList List of active botnets ObjectList

Details of fields in botnetDetailList:

Field Name Description Data Type
name Name of the active botnet String
botId If of the active botnet Number
ccCommunication C&C communication String
events Number of events Number
lastEvent Last event time String

Example

Request

GET https://<NSM_IP>/sdkapi/domain/0/activebotnets

Response

 {
       "botnetDetailList":
       [
           {
               "name": "IRCBots",
               "botId": 6,
               "ccCommunication": "UN_BLOCKED",
               "events": 1,
               "lastEvent": "Jan 31 10:04 IST"
           }
       ]
    } 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1105 Invalid domain
2 404 4201 Invalid duration filter